Cyber Security Analyst III - App Security and Vulnerability (Remote) at First Citizens Bank | Austin, TX, US | Rezi

Cyber Security Analyst III - App Security and Vulnerability (Remote) at First Citizens Bank

Cyber Security Analyst III - App Security and Vulnerability (Remote)

First Citizens Bank · Austin, TX, US

2 days ago

Cyber Security Analyst III - App Security and Vulnerability (Remote)

First Citizens Bank · Austin, TX, US

3 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Seeking a skilled Cyber Security Analyst with expertise in application security and vulnerability management to identify, analyze, and mitigate security risks using SAST, DAST, and SCA tools. This role involves leveraging modern security practices and emerging technologies, including AI/ML.

Responsibilities

  • Monitor and evaluate security incidents, system alerts, audit events, and other activity for potential threats.
  • Detect anomalies, malware infections, and intrusion attempts.
  • Identify, recommend, and execute mitigation tactics for identified threats.
  • Provide guidance and resolution for complex security issues.
  • Serve as an analytics resource for teams, management, and business units.
  • Support the design and implementation of new security products, services, procedures, and technologies.
  • Enable the defense of the organization’s information security and technological architecture.
  • Ensure all cyber security monitoring systems are online and fully operational.
  • Ensure compliance with all security policies and standards.
  • Analyze data from various operating systems, databases, and applications.
  • Source and interpret data to proactively search for threats.
  • Produce reports documenting investigations and security incidents.
  • Provide analytics and reporting for actionable cyber-intelligence.
  • Convey information to appropriate internal and external partners.
  • Leverage AI/ML-based security tools for enhanced detection and analysis.
  • Assess risks related to AI/ML models.
  • Participate in securing AI-driven applications and data pipelines.
  • Assess potential threats and attack vectors relevant to applications and APIs.
  • Apply threat modeling techniques during the development lifecycle.

Requirements

  • Knowledge of security event log analytics.
  • Knowledge of at least two of the following technologies: Firewall, Web-Proxy, IDS/IPS, Anti-Virus/Anti-Malware, Anti-Phishing, Malicious Web Site reporting or take-down.
  • Knowledge of at least three of the following: Insider Threats, Advanced Persistent Threats, Malware Analysis, Exploit techniques, Regular Expressions, SEIM Tuning, Alarm and Signature Creation.
  • Knowledge of Information Technologies with a focus in two or more of the following areas: operating systems, networking, computer programming, web development or database administration.
  • Understanding of Internet Protocol Suite networking, including routers, switches, public and private networks, internet protocol security, and virtual private networks.
  • Understanding of Packet Capture and analysis.
  • Knowledge of systems administration and analysis as well as risk management standards, procedures, and practices.
  • Bachelor's Degree and 6 years' experience in Information Security.
  • OR High School Diploma or GED/Equivalent and 10 years' experience in Information Security.
  • Hands-on experience with SAST, DAST, and SCA tools.
  • Hands-on experience with Web application security testing (OWASP Top 10, API security).
  • Strong understanding of Secure software development lifecycle (SDLC / DevSecOps).
  • Strong understanding of Common vulnerabilities (e.g., injection, XSS, authentication flaws).
  • Proficiency in one or more programming/scripting languages (e.g., Python, Java, JavaScript, Bash).
  • Experience interpreting and prioritizing scan results and remediation plans.
  • Experience integrating security tools into CI/CD pipelines (e.g., Jenkins, GitHub Actions, Azure DevOps).
  • Familiarity of container and cloud security (AWS, Azure, GCP).
  • Familiarity with AI/ML concepts and security implications.
  • Strong analytical and problem-solving skills.
  • Ability to communicate technical findings to both technical and non-technical stakeholders.
  • Experience working cross-functionally with development and engineering teams.
  • Attention to detail with a risk-based security mindset.
  • Experience with API security testing tools (Postman, SoapUI).
  • Experience with AI-assisted security tooling (e.g., anomaly detection, code analysis assistants).
  • Knowledge of regulatory frameworks (NIST, ISO 27001, SOC 2).

Skills

  • Application Security
  • Vulnerability Management
  • SAST
  • DAST
  • SCA
  • AI/ML
  • Security Incident Analysis
  • Threat Detection
  • Mitigation Tactics
  • Security Product Implementation
  • Information Security Architecture
  • Cyber Security Monitoring
  • Security Policy Compliance
  • Data Analysis
  • Threat Hunting
  • Reporting
  • Cyber-Intelligence
  • Firewall
  • Web-Proxy
  • IDS/IPS
  • Anti-Virus/Anti-Malware
  • Anti-Phishing
  • Insider Threats
  • Advanced Persistent Threats
  • Malware Analysis
  • Exploit Techniques
  • Regular Expressions
  • SEIM Tuning
  • Alarm and Signature Creation
  • Operating Systems
  • Networking
  • Computer Programming
  • Web Development
  • Database Administration
  • Internet Protocol Suite
  • VPN
  • Packet Capture
  • Systems Administration
  • Risk Management
  • Web Application Security Testing
  • OWASP Top 10
  • API Security
  • Secure Software Development Lifecycle (SDLC / DevSecOps)
  • Python
  • Java
  • JavaScript
  • Bash
  • CI/CD
  • Jenkins
  • GitHub Actions
  • Azure DevOps
  • Container Security
  • Cloud Security
  • AWS
  • Azure
  • GCP
  • Problem-Solving
  • Communication
  • Cross-functional Collaboration
  • Attention to Detail
  • Risk-based Security Mindset
  • Postman
  • SoapUI
  • NIST
  • ISO 27001
  • SOC 2
  • Threat Modeling
  • STRIDE

Location

  • Remote
  • NC
  • AZ
  • TX

Work Type

  • Remote
  • Full-time

Experience Level

  • 6 years experience
  • 10 years experience

Education Level

  • Bachelor's Degree
  • High School Diploma or GED/Equivalent

Benefits

  • Competitive, thoughtfully designed and quality benefits program

About the Company

  • First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates.